Vint Cerf spent more than two decades at Google after co-designing TCP/IP, the protocol that let independent networks talk to each other and became the internet. He left Google in July 2026. His next project is identity infrastructure for AI agents, and Luke Lango argues it could materially expand the AI infrastructure trade.
The thesis is straightforward once you state the problem. Most AI agents deployed in production today operate inside a single company’s firewall. A bank runs agents on internal risk data. A logistics company uses agents to optimize its own supply chain. A retailer deploys agents to manage procurement inside systems it controls. The compute demand from these internal workflows is real, and the companies supplying the chips, memory, networking, and power are already reporting it in earnings. But the demand is contained. The agents cannot leave the office because there is no reliable way for a receiving system to verify who sent an agent, what it is authorized to do, or who is accountable if something goes wrong.
Lango’s argument, published in his July 2026 InvestorPlace column, is that the highest-value agentic use cases require agents to cross organizational boundaries: a procurement agent negotiating directly with a supplier’s agent, a financial agent transacting in real time with a bank’s agent, a logistics agent coordinating across a dozen carriers’ systems, a healthcare agent pulling verified records from multiple hospital networks. Each generates inference compute demand that current projections do not model because the workflows cannot yet deploy at scale.
What DNSid Actually Does
Cerf joined the advisory council of Innovation Labs, a division of Identity Digital, on July 15, 2026. Innovation Labs had already submitted an Internet-Draft to the Internet Engineering Task Force on June 29 proposing DNSid, a framework for durable agent identity built on existing DNS infrastructure.
The specification is narrow by design. DNSid does one thing: it binds an AI agent to an accountable entity via a domain name. Each agent receives a Fully Qualified Domain Name, and the entity that controls that domain publishes DNS TXT records containing pointers to the agent’s cryptographic keys, a lifecycle log, and its operational status. The accountable entity signs the records. An append-only log records lifecycle events: issuance, key rotation, revocation, retirement, and migration.
The reason the log matters is that DNS is a current-state system. It tells you what a domain points to right now. It does not tell you who owned an agent at a specific point in the past, which is what post-incident forensics and regulatory audits require. The lifecycle log supplies the temporal property that DNS lacks. A verifier can determine which entity was accountable for an agent at the time an artifact was signed or a transaction was executed, even after the agent has been retired or its keys have rotated.
The IETF draft is explicit about what DNSid is not. It does not define authentication, authorization, policy enforcement, behavior monitoring, or runtime execution. It sits beneath existing standards like OAuth 2.1, OIDC, SPIFFE, and the Model Context Protocol. The draft calls this Layer 1, the durable accountable ownership anchor, and notes that the existing standards concentrate at Layers 2 through 7. Layer 1 was sparsely populated before DNSid.
The Pre-Internet Parallel
Lango draws the historical parallel directly. Before shared protocols, computer networks were islands, each organization running its own system with value but no easy way to communicate. Once a shared standard let networks talk to each other, the internet became a global market, and every person and institution needed to connect. The demand for routers, cables, servers, and the physical infrastructure underneath became essentially limitless.
The agentic web sits at the same inflection point. Today’s enterprise agent deployments look like the isolated networks of the 1980s. Valuable, growing, but fundamentally contained. A shared identity standard that lets agents operate across organizational boundaries, with accountability built in, would expand the addressable market for agentic infrastructure. Every cross-enterprise workflow becomes a candidate for agent-to-agent interaction, and each interaction requires inference compute, memory, networking, and storage.
The infrastructure thesis stays constant while the size of it grows. Lango’s framing is that the market understands enterprise agents but has not fully priced internet agents, or their larger workload.
Why Cloudflare Sits in the Flow
Lango identifies Cloudflare as potentially the cleanest public-market way to play the identity-and-routing layer. The reasoning is structural rather than promotional. Cloudflare already sits in the flow of internet traffic, security, authentication, and developer infrastructure. Its network spans 330-plus cities. If the agentic web moves beyond the enterprise firewall, the systems that route traffic and enforce access policies between agents and services become load-bearing infrastructure.
Cloudflare’s own product roadmap tracks the agentic thesis. In April 2026 the company launched Agent Cloud, a suite of infrastructure and developer tools for building, deploying, and scaling agents. The Agents SDK provides durable identity, state, scheduling, and recovery for agent sessions. In July 2026 Cloudflare introduced Mesh, a private networking layer that extends its Zero Trust platform to agent traffic, with the company stating it is building toward identity-aware routing where each node, device, and agent carries a distinct identity that policy engines can evaluate.
The connection to DNSid is that Cloudflare’s infrastructure already handles the routing, filtering, and policy enforcement that a verified agent identity layer would need to operate at scale. DNSid provides the identity anchor. Cloudflare provides the network that routes traffic to and from verified agents. The two layers are complementary rather than competitive.
The Inference Market Expansion
The core investment implication Lango draws is about market size rather than a specific stock pick. The physical infrastructure stack, the accelerators, high-bandwidth memory, optical networking, power, cooling, and storage, remains the core of the trade. That demand keeps growing, and the companies supplying it report it in earnings quarter after quarter. The DNSid layer, if adopted, adds a new source of demand on top of the enterprise workloads already running.
The mechanism is that cross-enterprise agent interactions are compute-intensive in ways that internal workflows are not. An agent operating across organizational boundaries must verify identity, negotiate terms, execute transactions, log audit trails, and handle exceptions. Each step generates inference calls. A single cross-enterprise procurement workflow between two companies’ agents could generate more compute demand than a hundred internal queries. Lango’s point is that the projections most investors work from model the internal workload. They do not model the cross-enterprise workload because it does not yet exist at scale.
The demand expansion depends on adoption, and DNSid is an Internet-Draft submitted in June 2026 that has not been ratified as a standard. Innovation Labs says it is trialing the system with several unnamed hyperscalers and identity companies, and the advisory council includes leaders from internet infrastructure, cybersecurity, national security, finance, and enterprise technology. Cerf’s involvement lends credibility, but standards adoption runs on its own timeline. The TCP/IP protocols Cerf co-designed took years to displace proprietary networking standards. The agentic identity layer will follow a similar path, compressed or extended by the urgency of the use cases pushing for it.
The Broader Identity Standards Landscape
DNSid is not the only project working on agent identity. The IETF draft itself acknowledges a layered ecosystem. OAuth 2.1 and OIDC handle runtime authentication. SPIFFE handles workload identity inside infrastructure-managed environments. The Model Context Protocol defines how agents discover and invoke tools. What none of these provide is a durable, governance-backed ownership anchor that persists across platforms, trust domains, and agent lifecycles. That gap is what DNSid targets.
Other proposals exist. The Agent Identity Protocol, another IETF draft, defines a decentralized identity and delegation framework using W3C Decentralized Identifiers. The ARIA Protocol, governed by a nonprofit foundation, proposes a DNS-anchored, post-quantum-native identity layer with graduated trust levels. Agent Passport is an open standard for verifiable business-issued identity published as a signed JSON file at a well-known URL. Each addresses a different layer of the same problem, and the standards will likely consolidate or interoperate over time.
What matters for the infrastructure thesis is whether any standard achieves sufficient adoption to let agents operate safely across organizational boundaries. The physical infrastructure that powers inference, memory, networking, and storage benefits regardless of which identity layer enables the traffic.
Where This Sits in Lango’s Stack
The DNSid thesis extends Lango’s AI toll roads framework. The toll roads argument held that agentic AI turns compute into a labor cost, and the infrastructure stack that handles agent traffic is the picks-and-shovels play. The toll road collects from every traveler regardless of which model powers the agent.
DNSid adds the premise that the road network is about to get longer. Today’s toll roads run inside enterprise firewalls. A verified identity layer would extend those roads across organizational boundaries, connecting previously isolated networks into a larger system. The toll operators, the companies that own the chips, memory, networking, power, and storage, collect from the expanded traffic.
Lango’s thesis stack now runs through seven layers. The Genesis Mission seeds the government capital. Acquisition Americana frames the resource-sovereignty macro. AI toll roads map the infrastructure stack. Physical AI covers the edge. Orbital Compute extends to space. Sovereign AI establishes the national security spending floor. The DNSid layer argues that the inference market itself is larger than current projections model, because the cross-enterprise agent traffic that would generate the largest compute demand cannot yet deploy at scale. When it can, the toll road expands.
See the guides index for the wider set of thesis explainers.